CVE-2016-3508

medium

Description

Unspecified vulnerability in Oracle Java SE 6u115, 7u101, and 8u92; Java SE Embedded 8u91; and JRockit R28.3.10 allows remote attackers to affect availability via vectors related to JAXP, a different vulnerability than CVE-2016-3500.

References

https://security.netapp.com/advisory/ntap-20160721-0001/

https://security.gentoo.org/glsa/201701-43

https://security.gentoo.org/glsa/201610-08

https://kc.mcafee.com/corporate/index?page=content&id=SB10166

https://access.redhat.com/errata/RHSA-2016:1477

https://access.redhat.com/errata/RHSA-2016:1476

https://access.redhat.com/errata/RHSA-2016:1475

https://access.redhat.com/errata/RHSA-2016:1458

http://www.ubuntu.com/usn/USN-3077-1

http://www.ubuntu.com/usn/USN-3062-1

http://www.ubuntu.com/usn/USN-3043-1

http://www.securitytracker.com/id/1036365

http://www.securityfocus.com/bid/91972

http://www.securityfocus.com/bid/91787

http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html

http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html

http://www.debian.org/security/2016/dsa-3641

http://rhn.redhat.com/errata/RHSA-2016-1776.html

http://rhn.redhat.com/errata/RHSA-2016-1504.html

http://lists.opensuse.org/opensuse-updates/2016-08/msg00028.html

http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00035.html

http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00034.html

http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00033.html

http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00032.html

http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00024.html

http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00011.html

Details

Source: Mitre, NVD

Published: 2016-07-21

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

Severity: Medium

CVSS v3

Base Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Severity: Medium